PowerProtect Data Manager: How to Configure Multi-VLAN for NAS Protection Engine

Summary: PowerProtect Data Manager (PPDM) version 20.3 supports multiple VLAN configurations for NAS Protection Engines. Multi-VLAN configuration segregates management and data traffic across different network segments. Existing protection engines cannot be modified with new VLANs after deployment. New NAS Protection Engines must be deployed with the required VLANs configured during the initial deployment. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

Understand the architectural constraint

PPDM has a significant limitation regarding network configuration. Existing protection engines cannot be configured with new VLANs after deployment. New network interfaces cannot be added to an already deployed NAS Protection Engine. To utilize additional VLANs, entirely new NAS Protection Engines must be deployed with the required VLANs configured during the initial deployment process.

Configure networks at PPDM Server level

Add the required VLANs to the PPDM Server Networks configuration first. The VLAN configuration follows a hierarchical structure where networks must be defined at the PPDM Server level before assignment to Protection Engines or assets. Add both the NAS VLAN and Data Domain VLAN to the PPDM Server Networks configuration before proceeding with Protection Engine deployment or asset configuration.

Deploy new NAS Protection Engines

Deploy new NAS Protection Engines with the required VLANs configured during the deployment wizard. Select the appropriate VLANs for management and data traffic during the deployment process. Existing Protection Engines cannot be modified with new VLANs, so new deployment is required for additional VLAN support.

Configure Data Domain network settings

Update the Data Domain network configuration in PPDM to include the new Data Domain VLAN interface. Configure this interface as Data or both Management and Data depending on requirements. Ensure that this Data Domain interface can properly communicate with the NAS Protection Engine on the designated data VLAN. The HA hostname and floating IP configuration may need adjustment to utilize the dedicated data VLAN specifically for backup traffic.

Configure VLAN preferences

Configure asset-level or policy-level VLAN preferences to control which network paths are used for specific backup operations. VLAN preferences can be configured at the asset source level, asset level, or policy level. Asset-level configuration takes higher precedence than asset source level configuration.

Configure search nodes for new VLANs

Configure search nodes for the new VLANs when using the Data for Management Components option. When a network is added with the Data for Management Components option, the search engine must be configured with the new VLAN to ensure proper functionality.

Ensure infrastructure network routing

Ensure proper network routing and firewall rules are configured at the infrastructure level to allow communication between all VLAN segments. PPDM can route traffic between the NAS Protection Engine and Data Domain on different VLANs, but proper infrastructure routing must be in place.

Migrate workloads to new Protection Engines

Consider migrating workloads from the old NAS Protection Engines to the new ones. Decommission the original engines if they are no longer needed after the migration process completes.

Note the communication limitation

PPDM cannot specify the exact network or VLAN for Protection Engine to NAS array communication. This communication happens over one of the network interfaces discovered as part of the NAS server configuration. If share mounting fails on one interface, PPDM automatically retries mounting over other available network interfaces.

Manage NAS server network interfaces

PPDM 20.3 provides enhanced capabilities for managing NAS server network interfaces. Preferred network interfaces can be added or specific interfaces can be excluded for asset sources. Interface names can be set for NAS network interfaces and named interfaces can be assigned to specific assets. Asset-level interface assignments override asset source level preferences. This granular control allows optimization of network path selection for NAS protection operations.

Note the container deployment limitation

Container-based deployments of PowerProtect Data Manager do not support multiple VLANs. Only OVA and cloud deployments support multiple VLAN configurations. This limitation must be considered when planning deployment architecture.

Additional Information

Article Properties
Article Number: 000506113
Article Type: How To
Last Modified: 09 أيلول 2026
Version:  1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.